Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
102 commits
Select commit Hold shift + click to select a range
3d6f6b1
Make LinxCore agent work reproducible and expose production-graph truth
Jul 30, 2026
8d2985c
Keep workload elaboration aligned with canonical load ownership
Jul 30, 2026
6f63cd9
Make canonical load ownership indivisible before cluster cutover
Jul 30, 2026
808990b
Tie speculative load state to the canonical launch event
Jul 30, 2026
d4b71a3
Make canonical load ownership the only execution path
Jul 30, 2026
9eda198
Prevent stale STQ returns from mutating canonical loads
Jul 30, 2026
60cba6e
Make the canonical LIQ validate every forwarding result
Jul 30, 2026
e55dfbe
Keep canonical load results alive across owner conflicts
Jul 30, 2026
6421670
Make canonical load forwarding survive production backpressure
Jul 30, 2026
71c6dc1
Make scalar load-store recovery production-safe
Jul 30, 2026
58b8093
Close the production scalar load ownership graph
Jul 30, 2026
4f11f8d
Make structural load blocking an owned lifecycle decision
Jul 30, 2026
709831c
Keep structural load retry implementation reviewable
Jul 30, 2026
f5bf1c8
Retain structural load uncertainty until ownership resolves it
Jul 30, 2026
a24be3a
Make structural load retry an exact LIQ mutation
Jul 30, 2026
e420e13
Close structural load blocking inside canonical ownership
Jul 30, 2026
294542f
Make structural load ownership auditable at the handoff
Jul 30, 2026
3cd6092
Make the core rewrite executable from one governed plan
Jul 31, 2026
8c5f1ed
Make the core contract independently reviewable before RTL moves
Jul 31, 2026
e656ace
Keep every width and resource choice explicit at one boundary
Jul 31, 2026
34e337d
Give every box one typed contract and one direction of authority
Jul 31, 2026
3bcbb84
Make template expansion a retained boundary instead of frontend glue
Jul 31, 2026
31d1f98
Make interface evolution traceable across the core rewrite
Jul 31, 2026
833c354
Make fixed-width instruction delivery independent of fetch geometry
Jul 31, 2026
7b1319e
Keep prediction speculative while recovery authority remains singular
Jul 31, 2026
7bf98da
Prove public IFU prediction coverage at each required boundary
Jul 31, 2026
983abd8
Record BF3 as a production observability gap
Jul 31, 2026
fdb1078
Prove BF3 only when ShortTage changes direction
Jul 31, 2026
5780f40
Preserve the reviewed IFU boundary evidence before OOO work begins
Jul 31, 2026
89f081e
Keep interface intent non-recursive and singly owned
Jul 31, 2026
54c05d7
Normalize every instruction form before speculative ownership begins
Jul 31, 2026
b46b0e8
Keep CTU repacking from stalling canonical OOO admission
Jul 31, 2026
70668f6
Preserve reviewed OOO admission evidence before rename begins
Jul 31, 2026
8b9443f
Preserve absolute and relative register semantics with separate owners
Jul 31, 2026
1574182
Make one ROB decision govern commit, traps, and precise cleanup
Jul 31, 2026
95126c0
Restore atomic owner readiness before precise cleanup
Jul 31, 2026
01e8dc4
Make Task 9 recovery and commit authority explicit
Jul 31, 2026
a0fb4ea
Repair canonical recovery arbitration with ROB authority
Jul 31, 2026
0ccbd2d
Make one ROB decision govern commit, traps, and precise cleanup
Jul 31, 2026
da5e850
Close recovery abort before apply can race
Jul 31, 2026
64b54af
Correlate ROB recovery responses to fired requests
Jul 31, 2026
f46c6a4
Drain mismatched ROB recovery responses legally
Aug 1, 2026
c92ff9e
Drain pre-request ROB responses without association
Aug 1, 2026
ae2fb07
Preserve BROB suffix-straddling blocks during recovery
Aug 1, 2026
ee89131
Preserve BROB recovery ring authority
Aug 1, 2026
83c8623
Bind BROB publication and target acks causally
Aug 1, 2026
989fc58
Refocus mainline migration on production-owner cutovers
Aug 1, 2026
2758fb0
Bind every ROB resident to causal BROB and recovery authority
Aug 1, 2026
3578344
Freeze one production owner before changing another boundary
Aug 1, 2026
b73be42
Make owner cutovers prove repository reality
Aug 1, 2026
3b4377d
Make owner manifests closed under repository identity
Aug 1, 2026
fad4d1e
Resolve manifest edges by Scala identity
Aug 1, 2026
c926bc6
Close owner manifest parser scope and call graph
Aug 1, 2026
a6b5a7b
Resolve fully qualified object apply emitters
Aug 1, 2026
0c99827
Record owner-manifest review closure before cutover
Aug 1, 2026
5f80ea0
Seal owner-manifest cutover gate after remote equality
Aug 1, 2026
1375436
Cut production dispatch onto one canonical OOO owner graph
Aug 1, 2026
dab252d
fix(ooo): close Task 11 review findings
Aug 1, 2026
5f95505
fix(ooo): close Task 11 rereview findings
Aug 1, 2026
3380edc
fix(ooo): harden public integration and doc gates
Aug 1, 2026
b2489cb
fix(ooo): synchronize retained commit ownership
Aug 1, 2026
f3530dc
test(ooo): prove Branch peer U tag survival
Aug 1, 2026
f89c38f
Plan the external TOP contract as an NDF refinement
Aug 1, 2026
bd3e42a
Prepare production IEX owners without creating a second core
Aug 1, 2026
19c4408
Align canonical IEX evidence with physical contracts
Aug 1, 2026
2d4cd5d
Prove retained IEX identity across every owner
Aug 1, 2026
86d76c4
Close the retained terminal evidence loop
Aug 1, 2026
2a1972c
Make the terminal fire payload fully observable
Aug 1, 2026
fdcbf3f
Plan the joint IEX LSU atomic cutover
Aug 2, 2026
8c55fd0
docs: freeze Task 13 IEX LSU contracts
Aug 2, 2026
682f74e
Freeze canonical OOO IEX LSU transactions
Aug 2, 2026
8ba5857
Harden canonical interface contract evidence
Aug 2, 2026
e652ca4
Bind OOO memory order and NFRDY to one publication
Aug 2, 2026
0177bc5
Design bounded Chisel simulation
Aug 3, 2026
a280bf3
Plan bounded Chisel simulation rollout
Aug 3, 2026
9358064
Supervise Chisel tests with build heartbeats
Aug 3, 2026
356cf3c
Route Chisel tests through supervised SBT
Aug 3, 2026
2d769a1
Close canonical OOO-IEX prerequisites
Aug 3, 2026
59e5d6e
Prepare the LSU two-pipe mechanism graph
Aug 3, 2026
b5326e6
Record Task 14 completion
Aug 3, 2026
c5ec847
Switch OOO IEX and LSU once and retire both reduced chains
Aug 3, 2026
923aea1
Fix Task 15 load replay ownership and bounded simulation
Aug 3, 2026
d72aed8
Fix Task 15 exact replay recovery and bounded gates
Aug 4, 2026
0f0f466
fix(task15): enforce Option A physical capacity boundaries
Aug 4, 2026
51a6921
Fix Task 15 identity widths and active wrapper docs
Aug 4, 2026
3c45147
Fix Task 15 planner widths and evidence docs
Aug 4, 2026
1762266
Add exact provenance to Task 15 evidence
Aug 4, 2026
3c8e2f9
Clarify deleted replay locator evidence
Aug 4, 2026
41611fc
Complete continuous OOO D3 cutover
Aug 4, 2026
07ec265
Close memory and recovery inside the one live LSU owner
Aug 4, 2026
d5609fe
Close Task 16 review findings round 1
Aug 4, 2026
116867a
fix(lsu): close round 2 memory review findings
Aug 4, 2026
ff02aef
fix(lsu): fail closed ownership responses
Aug 4, 2026
1bdaaf5
Keep debug observable without creating a second control machine
Aug 4, 2026
cdda611
Keep terminal progress independent of trace export
Aug 4, 2026
e0c90c2
Separate terminal acceptance from trace observation
Aug 4, 2026
8697fa1
Expose one routable core without moving ownership into TOP
Aug 4, 2026
4ab63ea
docs: design LinxCore core architecture diagram
Aug 5, 2026
656f0a0
docs: plan LinxCore architecture diagram
Aug 5, 2026
692e378
docs: add LinxCore core architecture diagram
Aug 5, 2026
47b7ce2
docs: update active uop classification pointer from v0.56.5 to v0.57
Aug 5, 2026
ed18b0d
chisel: advance natural W2 owner closure
Aug 11, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
3 changes: 3 additions & 0 deletions .gitmodules
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
[submodule "tools/superpowers"]
path = tools/superpowers
url = https://github.com/obra/superpowers.git

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
@@ -0,0 +1,110 @@
# Task 17 report: distributed control and DTU observation

## Outcome

Task 17 adds one typed DTU observation boundary without moving commit,
trap, interrupt, debug-boundary, or recovery decisions out of OOO. DTU now
transports external halt/resume requests to the OOO owner, exports a
loss-tolerant trace stream, and publishes monotonic observation counters.

OOO retains halt requests until the requested STID reaches a precise commit
boundary. Synchronous faults take priority over debug and interrupts, and
interrupt selection excludes requests for another STID. Recovery continues to
use one common Prepare/Prepared/Apply barrier, while CTU fences only the target
STID so unrelated work can progress.

No displaced stateful debug, trace, or system-control wrapper was named by the
closed-owner inventory. `CommitTraceMonitor` remains a stateless checker used
by legacy ROB fixtures and is not a competing DTU or commit owner, so this task
deleted no wrapper.

## Implementation

- Added `DTU`, `DebugControl`, `TraceExport`, and `PerformanceCounters`.
`DebugControl` is a one-entry typed transport queue; it does not interpret a
command or select a boundary. `TraceExport` always accepts observations and
retains at most one externally visible packet. Counters never qualify a
control ready/valid path.
- Extended `DTUIO` with the owner-facing debug channel, trace export, and
counter vector. Extended `OOOIO` and the D3/S1 graph with the matching typed
debug channel.
- Added OOO-owned halt state and debug response generation to
`CommitControl`. A pending halt survives a higher-priority synchronous fault
and is applied at the next matching precise boundary. Resume clears the
halted state.
- Qualified both commit and recovery interrupt arbitration by the boundary
STID before priority reduction.
- Made CTU recovery admission, buffered output, and trace fences local to the
plan target STID.
- Instantiated DTU in the canonical OOO/IEX/LSU activation graph and connected
commit, trace, and debug control paths without adding an adapter owner.
- Updated the interface manifest, closed-owner manifest, checker tests, and
L1/L2/L3 behavior contracts.

## TDD evidence

The initial `DTUSpec` and `RecoveryIntegrationSpec` failed to compile because
`linxcore.dtu.DTU` and its mechanisms did not exist. The first behavior run
then exposed two distributed-control failures: interrupt reduction selected a
higher-priority request for the wrong STID, and CTU recovery fencing blocked
unrelated-STID admission. A separate debug-boundary RED proved that
`CommitControl` had no typed halt/resume input or OOO-owned halted state.

The focused fixes closed those failures without changing public identity
widths or the memory attempt-ownership contract.

## Verification

- `DTUSpec` — PASS, 4/4. Artifact size 167,214,581 bytes under a
300,000,000-byte cap.
- `RecoveryIntegrationSpec` — PASS, 5/5. Artifact size 382,485,994 bytes under
the task's 900,000,000-byte cap.
- `CommitControlDebugSpec` — PASS, 1/1. One simulation covers normal commit,
precise same-STID interrupt selection, synchronous-fault priority over a
pending halt and interrupt, debug halt, and resume. Artifact size 87,755,548
bytes under a 300,000,000-byte cap.
- `RecoveryControlBarrierSpec` — PASS, 1/1. One simulation covers single
prepare fanout, missing-acknowledgement stall, and common apply. Artifact
size 60,756,922 bytes under a 300,000,000-byte cap.
- `CTUSpec` — PASS, 11/11.
- `OOOCommitApplyPolicySpec` — PASS, 1/1.
- `bash tests/test_trace_schema_and_mem.sh` — PASS. Its negative-path fixture
intentionally prints `error: missing trace output`.
- `python3 tools/chisel/trace_schema_adapter.py --self-test` — PASS.
- `python3 tools/chisel/render_top_interface_manifest.py --check` — PASS; the
checked-in manifest is current.
- `python3 tools/chisel/check_production_owner_manifest.py` — PASS: 27 closed
owners, 24 classified emitters, 6 declared adapters, and L1/L2/L3 roles
mapped.
- `python3 -m unittest tests.test_production_owner_manifest -v` — PASS, 46/46.
- `git diff --check` — PASS.

`OOORobCommitSpec` was stopped as a resource failure rather than classified as
a test failure: status 130, child status -9, 1,832,601,201 artifact bytes, and
3,490,054,144 peak process-tree RSS. It was not rerun. Inspection found that
`chisel_test_supervisor.py` checks the artifact budget only after a successful
child exit, so the configured cap reports an excess but does not enforce it
during elaboration. The supervisor was not changed because no independent RED
for that tool is part of Task 17.

The NDF local-reference checker still reports the pre-existing unrelated gap
`docs/spec/40-constraints/parameters.md:72: missing verifies edge for L1 MUST
PRM-LSU-SIZING-001`. Task 17 did not modify that parameter contract.

## Source identities

- LinxCore baseline: `ff02aefaba8822b53f6fecf40e941017973ab961`
- LinxISA superproject: `54635e8cb111`
- LinxCoreModel reference: `3ca25e05d2a2`
- QEMU reference: `c9f9570aa70d`

## Assumptions and limits

- Trace export is deliberately loss-tolerant. A retained packet remains stable
while stalled; a newer observation may be counted and dropped.
- The existing OOO/IEX/LSU activation graph is the smallest live caller before
Task 18 assembles TOP. DTU ownership and wiring therefore remain explicit
without prematurely creating the final top-level composition.
- Six pre-existing x86 firtool processes remain in kernel-uninterruptible
state. They are unrelated to Task 17; reproducible Task 17 build artifacts
are removed before handoff.
Original file line number Diff line number Diff line change
@@ -0,0 +1,77 @@
# Task 17 review fixes — round 1

## Finding addressed

The activation caller previously connected DTU to the permanently invalid OOO
trace output while the live IEX trace bypassed DTU and inherited external
backpressure. `IEX` also generated its public terminal PWrite observation from
the trace arbiter output fire, so that observation disappeared when the trace
consumer stalled.

## RED evidence

`DTUActivationTraceSpec` initially stalled the activation probe's external IEX
trace consumer and issued terminal operations. The test failed with
`rfWriteCount=0` where two terminal PWrite observations were required.

The first elaboration attempt also exposed stale activation-harness tie-offs
for the existing LSU maintenance and memory-fault ports. Those ports were tied
to inert values before recapturing the behavioral RED. They are unrelated to
the trace ownership change.

The precise behavioral RED used 595,635,289 artifact bytes and failed only on
the expected terminal PWrite suppression.

## Ownership correction

- The only live trace producer in the OOO/IEX/LSU activation graph is IEX;
current OOO and LSU trace outputs are explicitly invalid. The caller now
connects `iex.io.trace` directly to DTU's always-accepting trace ingress.
- The former `iexTraceReady` activation input now controls DTU's external trace
export only. Stalling it can retain or drop observations but cannot
backpressure IEX.
- DTU remains the sole loss-tolerant export owner. No trace adapter or second
trace state owner was added.
- `IEX` records a typed terminal PWrite observation when the corresponding
terminal source actually fires. Per-source pending observations are selected
independently of trace-arbiter fire and trace output readiness. This retains
the exact ROB, tag, generation, and value without deriving architectural
progress from an observational handshake.

## Behavioral proof

The compact W4 activation test uses four ROB groups and four BROB entries while
preserving all public identity widths. It issues one valid closed block:

`BSTART_FALL -> ADDI -> ADDI -> BSTOP`

The external DTU trace export remains stalled throughout. The first packet is
retained and checked stable for three cycles. The second packet overflows the
one-slot exporter and is counted as dropped while both terminal writes,
completion publication, and commit continue.

Final exact counters:

- terminal PWrite observations: 2
- resolve completions: 2
- commit transactions: 1
- DTU accepted trace observations: 2
- DTU dropped trace observations: 1

## Verification

- `DTUActivationTraceSpec` — PASS, 1/1; 586,754,201 artifact bytes, 564
files, 145.464 seconds, peak process-tree RSS 7,593,181,184 bytes.
- `DTUSpec` — PASS, 4/4; 167,214,581 artifact bytes under a
300,000,000-byte cap.
- New IEX elaboration warnings — none. The final selector emitted only the
repository's generic multiple-main-class warnings.
- `python3 tools/chisel/check_production_owner_manifest.py` — PASS: 27 closed
owners, 24 classified emitters, 6 declared adapters, and L1/L2/L3 roles
mapped.
- `python3 -m unittest tests.test_production_owner_manifest -v` — PASS, 46/46.
- `git diff --check` — PASS.

The owner manifest was updated only after the activation behavior passed. It
now names `DTUActivationTraceSpec` as activation-level evidence for the live
DTU caller.
Original file line number Diff line number Diff line change
@@ -0,0 +1,79 @@
# Task 17 review fixes — round 2

## Findings addressed

`OooIexTerminalPublish` previously included trace readiness in the atomic
terminal rendezvous. The IEX boundary also derived its public terminal PWrite
observation from trace-source fire and fed observation capacity backward into
that source's ready signal. A stalled or full observation path could therefore
delay architectural completion.

## RED evidence

The focused `IEXTerminalTraceIndependenceSpec` held `trace.ready` low while
every required architectural sink was ready. Against the round-1 base it
failed at the first architectural check: `alu.ready` was zero instead of one.
The focused behavioral RED used 113,563,306 artifact bytes across 110 files,
below its 200,000,000-byte cap.

After the first independence repair, the exact activation assertions exposed
a second behavioral RED: `rf=1 resolve=2 commit=1 accepted=2 dropped=1`. Two
architectural terminal lanes completed together, but a combinational
single-output observation selector retained only one PWrite observation.

An earlier attempt to use the full legacy terminal suite was stopped after its
one-simulator-per-case shape exceeded the compact resource target. A separate
setup attempt passed an executable instead of the firtool directory to
`CHISEL_FIRTOOL_PATH`. Neither attempt is classified as behavioral evidence.

## Architectural acceptance

- `OooIexTerminalPublish` now defines `architecturalReady` solely from the
required ROB resolve, physical-file write, wakeup, recovery-event, and BCTRL
endpoints. Trace ready, trace queue state, DTU state, and export state do not
participate.
- One `architecturalFire` releases the selected terminal owner and atomically
drives required architectural completion, PWrite, wakeup, recovery, and
BCTRL outputs. The terminal trace valid pulse is generated from that event
as a best-effort observation; trace acceptance is not asserted as part of
architectural fire.
- A private typed `architecturalAccepted` observation carries the exact
accepted request through TerminalFabric, ExecutionCluster, and
ExecutionPipeline. IEX no longer reconstructs terminal PWrite observation
from trace fire.
- Trace-source ready is hard true at the IEX observation boundary. Local trace
queues may miss a pulse when full, but cannot stall architectural acceptance;
DTU remains the sole external loss/accounting owner.

`IEXIO.terminalPWrite` is explicitly a `Valid[IEXTerminalPWriteObservation]`,
not an RF mutation port or state owner. The real architectural PWrite ports
remain the Decoupled outputs of `OooIexTerminalPublish` connected to the
operand files. Per-lane retained observations serialize simultaneous terminal
events without feeding capacity into architectural readiness. Consume and
same-lane replacement are atomic, and an assertion forbids silent observation
overflow.

## GREEN evidence

- `IEXTerminalTraceIndependenceSpec` — PASS, 1/1. With trace ready low, one ALU
owner acceptance, exact PWrite data, wakeup, ROB resolve, and terminal fire
occur once; the following three cycles contain no duplicate. Final artifact
size was 115,360,634 bytes across 110 files under the 200,000,000-byte cap;
elapsed time was 13.180 seconds and peak process-tree RSS was 2,736,242,688
bytes.
- `DTUActivationTraceSpec` — PASS, 1/1. With the external DTU export stalled,
the retained packet remains stable and final counters are exact:
`rf=2 resolve=2 commit=1 accepted=2 dropped=1`. Final artifact size was
586,772,137 bytes across 564 files under the 900,000,000-byte cap; elapsed
time was 147.043 seconds and peak process-tree RSS was 7,541,555,200 bytes.
- `DTUSpec` — PASS, 4/4. Artifact size was 167,214,581 bytes across 198
files under the 300,000,000-byte cap; elapsed time was 14.575 seconds and
peak process-tree RSS was 1,667,006,464 bytes.
- The closed-owner manifest checker passed with 27 closed owners, 24
classified emitters, 6 declared adapters, and all L1/L2/L3 roles mapped.
Its 46-case unit suite, the top-interface manifest check, and
`git diff --check` also passed.

Both final suites used the repository wrapper, one job, a clean build
directory, and the native arm64 firtool override. `OOORobCommitSpec` was not
run.
Loading